Latest cyber news, threats, security, and guidelines. Stack up.

Advisories

Wed 2 Sep

StreamRat Android banking trojan pushed via Meta ads to Spanish-speaking users

ThreatFabric (2 September 2026) details StreamRat, an Android banking trojan promoted through a fake television-streaming campaign on Meta aimed at Spanish-speaking users. ThreatFabric estimates about 570,950 Meta accounts in the EU saw the ad at least once; infected-device totals are not published. After sideloading app.apk, the dropper seeks default Home-app status, a VPN permission that blackholes other apps' traffic during install, unknown-sources install rights, then Accessibility access for the StreamRat payload (keylogging, credential overlays, UI inspection, remote control) before talking to C2. ThreatFabric does not name an attributed actor. Users should refuse streaming APKs that request Home, VPN, or Accessibility controls unrelated to playback; enterprises with BYOD Android in AU/EU travel cohorts should watch for sideloaded streaming lures.

ThreatFabric StreamRat analysis (2 Sep 2026)

tech identity

Advisories

Wed 2 Sep

Sality P2P botnet infrastructure disrupted in joint global takedown

BleepingComputer and SecurityWeek report a 2 September 2026 joint disruption of the long-running Sality peer-to-peer botnet. Europol, Eurojust, the U.S. DOJ, FBI and DCIS seized Sality-linked domains in the United States, with further seizures in Bulgaria, Hungary and Romania. CrowdStrike's Counter Adversary Operations, with law-enforcement and industry partners, sinkholed known super-peer lists that form the botnet's communication backbone, blocking file packs and URL packs that push payloads. CrowdStrike says Sality has been active since at least 2003, has infected more than 15,000 devices historically, and that the two still-active networks at takedown were mainly used to push EggJagger clipjacking payloads; earlier payload history spans credential theft, spam, proxies, exploitation and DDoS. BC quotes CrowdStrike that after more than two decades the botnet is now no longer able to push new malware payloads through those channels.

BleepingComputer

tech network

Advisories

Tue 1 Sep

Microsoft: counterfeit software installers disable Defender and Windows Update (Silver Fox-linked)

Microsoft Security Blog (1 September 2026) details an active campaign of high-fidelity fake vendor download sites (.com.cn / .hl.cn lookalikes for brands including Microsoft Edge, Razer, Kaspersky, Sejda, Calibre and others) that serve ZIP installers whose hashes rotate per download. Payloads establish persistence via disguised scheduled tasks, write sweeping Microsoft Defender exclusions (including short-lived SYSTEM tasks), delete volume shadow copies, stop/disable Windows Update services (wuauserv, UsoSvc, uhssvc, WaaSMedicSvc), and C2 on non-standard ports (e.g. 5090, 7031–7090, 8050, 28290, 28300) plus six-character .net domains. A parallel path uses msiexec -Embedding. Microsoft assesses with moderate confidence consistency with the publicly reported Silver Fox (Yinhu) fake-software campaign but does not attribute a nation-state. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, primarily China-based operations / Chinese-speaking users. Primary mitigations Microsoft names: Tamper Protection, SmartScreen/network protection, hunt randomized drops under Public/ProgramData/Program Files (x86), and block look-alike ZIP download patterns.

Microsoft Security Blog (1 Sep 2026)

tech identity network

Advisories

Tue 1 Sep

Privacy Act draft: 72-hour OAIC eligible-breach notification (consultation)

iTnews (1 September 2026) reports the Attorney-General's Department released the Privacy Amendment (Personal Data Protection) Bill 2026 for consultation. The draft would replace the Notifiable Data Breaches scheme's "as soon as practicable" OAIC notification standard with a fixed 72-hour deadline once an entity has reasonable grounds to believe an eligible data breach has occurred, aligning NDB timing with 72-hour windows used under the Security of Critical Infrastructure Act 2018 and ransomware-payment reporting in the Cyber Security Act 2024. The existing 30-day window to assess a suspected breach would remain; entities unable to file a complete statement in time could lodge an incomplete one with written notice of what is missing. Failing to file within 72 hours could attract an infringement or compliance notice. The same package proposes a narrow erasure right limited to large digital platforms (Online Safety Act services clearing $500m gross revenue or 2.5 million average monthly Australian end users), not an economy-wide deletion duty. This is draft consultation legislation, not yet enacted.

iTnews

australia

Advisories

Tue 1 Sep

Kaspersky: Mirage Kitten (Nimbus Manticore) ships NodeRabbit and PollCat RATs

Kaspersky Securelist published on 1 September 2026 that Iranian APT Mirage Kitten (also tracked as Nimbus Manticore, UNC1549, Smoke Sandstorm) is using two previously undocumented cross-platform RATs: NodeRabbit (Node.js) and PollCat (obfuscated JavaScript), the first publicly documented Node.js and JavaScript malware from this group. Operators deliver the implants through recruiter personas on LinkedIn and other job platforms, using trojanized coding-challenge archives. Kaspersky found NodeRabbit samples on systems in Afghanistan, Egypt and Ethiopia. PollCat was recovered from a RankChallenge-react assessment archive. The group has historically used C, C++ and Go malware against aviation, aerospace and fintech in the Middle East and Africa. Kaspersky detections: Trojan.JS.MirageKitten.*.

Kaspersky Securelist (1 Sep 2026)

tech

Advisories

Mon 31 Aug

Gryxa: AI-built Windows toolkit watches defender cleanup and fights back

ReliaQuest Threat Research describes Gryxa, a financially motivated Windows toolkit ReliaQuest assesses was substantially built with a commercial AI coding agent (AI co-author metadata on most commits in the actor's public repo). Delivery is likely an invoice-themed 19 MB SFX (invoice_<10 digits>.exe). After the visible RMM implant is removed, a surviving component collects Windows logs and host artefacts and uploads them so the operator sees the remediation. If the actor's relay is unreachable for two consecutive five-minute checks, Gryxa disables Defender and listed EDR; at three failures it attempts a silent uninstall. ReliaQuest's analysis of the actor console listed 324 hosts (69 reporting online at the time of writing); not every listed host is a confirmed victim. Credential theft targets Chromium saved logins (including App-Bound Encryption bypass paths in code) and flags wallet extensions. IoCs (defanged): wirbe[.]com, seczio[.]com, gryxa[.]com, sevrz[.]com and related hosts in ReliaQuest's table. Cyber Security News 31 August. Do not invent CVSS.

ReliaQuest (Gryxa threat spotlight)

ai identity

Advisories

Sun 30 Aug

Fire Ant: China-nexus actor hijacks Cisco IOS XR, TACACS (TacTap) and Linux management hosts

Sygnia's 30 August 2026 report (The Hacker News 31 August) says Fire Ant, first reported in 2025 and assessed to overlap UNC3886, remained active into 2026 and expanded from hypervisors into trusted infrastructure: Cisco IOS XR routers, TACACS authentication, and Linux management hosts. Router implants (including a masqueraded grub-rommon service launching /usr/bin/acpid) suppressed selected syslog, hid CLI output, and supported GRE tunnels. On the tunnel far-end, BridgeAgent persisted as zabbix_agent.service (filename zabbix_agent, not the legitimate zabbix_agentd) — a Zabbix-name masquerade, not a Zabbix product CVE. TacTap injects /lib/libseconfd.so into tac_plus to steal credentials to /var/log/.tacplus.acct (XOR 0xEF). Sygnia also describes Medusa-related Linux access, custom SSH backdoors, and REPTILE-like packet-triggered implants. Treat routers, TACACS and jump hosts as first-class forensic assets. Primary: Sygnia.

Sygnia (30 Aug 2026)

tech network

Advisories

Sun 30 Aug

Anthropic: infostealers hijacking Claude sessions to drain usage

On 30 August 2026 BleepingComputer reported Anthropic emails to affected Claude users: infostealer malware on already-compromised PCs stole active Claude login sessions, then used those sessions to access accounts and consume usage (including usage that appeared to refill then drain). Anthropic is signing affected users out, removing saved payment methods, and refunding charges it identifies as unauthorised. Anthropic says it has no reason to believe the malware was installed through Claude. It has identified Vidar, LummaC2, StealC, RedLine and Acreed on Windows, and Atomic Stealer (AMOS) on a small number of Macs. Signing out stops the stolen session; it does not remove the malware. No CVSS. No public Anthropic advisory page at the time of writing; desk source is BleepingComputer quoting the company email.

BleepingComputer (30 Aug 2026)

ai identity

Advisories

Fri 28 Aug

HexMage Magecart: EtherHiding on Ethereum Sepolia to skim e-commerce checkouts

Confiant (28 August 2026; figures as of 25 August) tracks HexMage, a Magecart cluster that injects a fake Google Tag Manager block into compromised storefronts (mostly WooCommerce), loads ethers.js, and reads a Sepolia testnet contract to obtain a disposable skimmer host (EtherHiding). Confiant observed 40+ impacted sites across at least 15 countries since about April 2026; 25 storefronts mapped, including Australian site protocoffee[.]com[.]au (a blockchain-free loader variant pointing at stylerightnoww[.]com). One owner wallet (0x88361C914Bb0942da9a1b7Bb396a7513C1917aee) had deployed 144 contracts by 21 July 2026. The skimmer overlays the payment form, harvests PAN/expiry/CVV, then restores the DOM so the purchase completes. Fake-GTM detection: the injected block never fetches googletagmanager[.]com/gtm.js. Cyber Security News carried the story on 31 August. Defanged names only on this desk — not live links.

Confiant (28 Aug 2026)

tech australia

Advisories

Fri 28 Aug

TerminalFix: fake Cloudflare CAPTCHA pushes a reverse-tunnel via Windows Terminal

Microsoft Threat Intelligence (Security blog dated 28 August 2026; JSON-LD published 29 August) describes TerminalFix, a ClickFix variant that uses compromised websites and a fake Cloudflare CAPTCHA overlay to trick users into pasting a PowerShell command in Windows Terminal or PowerShell rather than the Run dialog. The command downloads a ZIP with a legitimate LockScreenContentServer.exe binary and a malicious dui70.dll for DLL sideloading. Later stages pull payloads hidden in PNG images, persist via Registry Run keys and scheduled tasks, run Active Directory reconnaissance, and deploy a Python reverse-tunnel implant that proxies TCP over an encrypted WebSocket. Microsoft says it did not observe the later hands-on-keyboard steps (privilege escalation, defence tampering, ransomware) in the analysed chain, but treats affected hosts as potential network pivot points. Distinct from the older ClickFix/Vidar WordPress campaign already on this desk. Primary: Microsoft. Secondary: The Hacker News 30 August.

Microsoft Security Blog (28 Aug 2026)

tech identity network

Advisories

Thu 27 Aug

Chrome and Edge extensions delivering wallet-drainer malware (Superior)

Socket Threat Research (published 27 August 2026) identified 18 Chrome Web Store extensions and one Microsoft Edge add-on that deliver an extensible malware framework Socket tracks as Superior. Five of the extensions had been acquired from original creators and later pushed malicious updates to existing users; one right-click utility had around 70,000 Chrome users (and about 10,000 on Edge) when malicious functionality appeared. Modules establish encrypted WebSocket C2, strip Content Security Policy headers, and inject payloads that drain crypto wallets, steal credentials and browser history, harvest social accounts, and show ClickFix-style fake update prompts. Google removed the Chrome listings; Socket reported the Edge variant was still live when it published (Edge C2 rotated on 14 August 2026). Users who installed any listed extension should treat credentials as compromised and move crypto to a fresh wallet. Primary: Socket. Secondary: BleepingComputer 30 August.

Socket Threat Research

tech identity cloud

Advisories

Thu 7 May

ClickFix via compromised WordPress sites distributing Vidar Stealer

ASD's ACSC has observed ClickFix social-engineering activity using compromised WordPress sites to distribute Vidar Stealer against Australian infrastructure. Treat unexpected 'paste this command' prompts as hostile. This is social engineering, not an AI-stack flaw.

ASD's ACSC advisory

australia social engineering